CVE-2026-43569

OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto-enabled during non-interactive onboarding when provider auth choices are shadowed. Attackers can exploit this by crafting malicious workspace plugins that are automatically selected and enabled during authentication setup without explicit user consent.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-05-05 12:16

Updated : 2026-06-17 10:49


NVD link : CVE-2026-43569

Mitre link : CVE-2026-43569

CVE.ORG link : CVE-2026-43569


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-829

Inclusion of Functionality from Untrusted Control Sphere